config defaults
option syn_flood 1
- option input DROP
+ option input ACCEPT
option output ACCEPT
- option forward DROP
+ option forward REJECT
+# Uncomment this line to disable ipv6 rules
+# option disable_ipv6 1
config zone
option name lan
+ option network 'lan'
option input ACCEPT
option output ACCEPT
- option forward DROP
+ option forward REJECT
config zone
option name wan
- option input DROP
+ option network 'wan'
+ option input REJECT
option output ACCEPT
- option forward DROP
+ option forward REJECT
option masq 1
+ option mtu_fix 1
config forwarding
option src lan
option dest wan
+# We need to accept udp packets on port 68,
+# see https://dev.openwrt.org/ticket/4108
+config rule
+ option src wan
+ option proto udp
+ option dest_port 68
+ option target ACCEPT
+ option family ipv4
+
+#Allow ping
+config rule
+ option src wan
+ option proto icmp
+ option icmp_type echo-request
+ option target ACCEPT
+
+# include a file with users custom iptables rules
+config include
+ option path /etc/firewall.user
+
### EXAMPLE CONFIG SECTIONS
# do not allow a specific ip to access wan
# option dest_port 80
# option proto tcp
-# include a file with users custom iptables rules
-#config include
-# option path /etc/firewall.user
+# port redirect of remapped ssh port (22001) on wan
+#config redirect
+# option src wan
+# option src_dport 22001
+# option dest lan
+# option dest_port 22
+# option proto tcp
+# allow IPsec/ESP and ISAKMP passthrough
+#config rule
+# option src wan
+# option dest lan
+# option protocol esp
+# option target ACCEPT
+
+#config rule
+# option src wan
+# option dest lan
+# option src_port 500
+# option dest_port 500
+# option proto udp
+# option target ACCEPT
### FULL CONFIG SECTIONS
#config rule